CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++

Sdk For ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions <= 1.11.861
Regions all
CVE IDs CVE-2026-19642, CVE-2026-19643
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update the AWS SDK for C++ to version 1.11.862 to address critical memory-safety issues in the Base64 decoder and ensure the application's process performing the decode remains stable and secure.

For Platform Teams

Adopt the updated AWS SDK for C++ version 1.11.862 to integrate the new Base64 implementation from the AWS Common Runtime, enhancing the platform's security and stability.

For Executives

Implement the upgrade to AWS SDK for C++ version 1.11.862 to mitigate security vulnerabilities (CVE-2026-19642 and CVE-2026-19643) and ensure application stability and security.

Source

View original AWS announcement โ†’

Related Sdk For Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.